PRIVACY & DATA PROTECTION

Privacy Policy

How Shielded Networks collects, uses, shares, secures and retains personal data — across our website, our services and our engagements. We are a cybersecurity business, and we hold our own handling of personal data to the standard we ask of our clients.

Effective date: 29 August 2026   ·   Last updated: 30 August 2026

ON THIS PAGE

Contents

Sections 1–7

Our commitment · Who we are and our role · Scope · Personal data we may collect · Sensitive data · How we collect it · Why we use it

Sections 8–13

Legal bases · Cookies and similar technologies · Analytics · Marketing · Sharing and disclosure · Processors and subprocessors

Sections 14–18

International transfers · Security · Personal data incidents · Retention · Deletion and destruction

Sections 19–26

Your rights · Making a request · Complaints · Children · Third-party sites · Business transfers · Changes · Contact us

1. Our commitment to privacy

Shielded Networks provides cybersecurity, network and IT infrastructure services to organisations. Handling other people’s information carefully is not a side concern for us — it is the substance of what our clients engage us to do. We apply the same expectation to the personal data we hold ourselves.

This policy explains, in plain terms, what personal data we may collect, why we use it, who we may share it with, how long we keep it, how we protect it, and what choices and rights you may have. It is written to be read by people who are not lawyers, while remaining detailed enough for procurement, vendor-assurance and security review teams.

2. Who we are and the role we play

Shielded Networks FZCO, registered in the United Arab Emirates in the Dubai Silicon Oasis free zone, and Shielded Networks (SMC-Private) Limited, registered in Pakistan with the Securities and Exchange Commission of Pakistan, are two affiliated companies under common ownership. They trade together as Shielded Networks and share this website, the shieldednetworks.com email domain and the email services behind it. In this policy “we” means whichever of the two entities is responsible for the personal data in question — ordinarily the entity that holds the client relationship or that you contacted. We serve clients across the UAE, the wider GCC, Pakistan and other markets.

Our role in relation to personal data depends on the circumstances, and this distinction matters because different obligations follow from it:

When we decide why and how personal data is processed — for example data collected through this website, our own marketing, our supplier relationships and our recruitment — we act as the controller of that data.

When we process personal data on a client’s instructions as part of delivering a service, such as a security assessment, a managed service or an infrastructure project, we generally act as a processor (a service provider) for that client, who remains the controller.

Where we engage another organisation to help deliver a service that involves client personal data, that organisation may act as a subprocessor, engaged under written terms.

Where we act as a processor, the client’s own privacy notice and our contract with them govern that processing, and this policy does not replace either. Where a service agreement, data processing agreement or statement of work says something different from this policy about a specific engagement, that agreement takes precedence for that engagement.

3. What this policy covers

This policy applies to the Shielded Networks website at www.shieldednetworks.com, to enquiries and communications you send us, to our marketing and business development activity, to our dealings with clients, prospects, partners and suppliers, and to applications for roles with us.

It does not cover personal data we process solely on behalf of a client under that client’s instructions, which is governed by our contract with them. It also does not cover third-party websites or services that we link to.

4. Personal data we may collect

We collect only what we reasonably need for a legitimate business or service purpose. Depending on how you interact with us, that may include:

Identity and business contact details — your name, business email address, telephone number, employer or organisation, job title and country.

Enquiry content — the message, description of requirements and services of interest you provide when you contact us, together with anything else you choose to include.

Client and contract records — contact details for the people we deal with at a client or supplier, contractual documents, purchase orders, invoicing and payment records, and correspondence.

Technical and website data — IP address, browser and device characteristics, pages requested, and similar information generated automatically when you visit the site.

Security and operational logs — records generated to keep the website and our systems available, to detect and investigate abuse, and to support incident response.

Marketing preferences — whether you have asked to receive material from us and any subsequent choices you make.

Recruitment information — where you apply to work with us, the details in your application, CV and professional history.

Engagement material — information that reaches us during an authorised service engagement, described further in section 5.

You are not obliged to give us personal data, but if you do not provide business contact details we may be unable to respond to an enquiry or to provide a service.

5. Sensitive information and engagement data

We do not ask for sensitive personal data — such as health information, biometric data, or details of religious or political views — through this website, and we ask that you do not send such information to us through the website forms.

Cybersecurity work is different. During an authorised engagement such as a penetration test, a vulnerability assessment or an incident investigation, material we encounter may incidentally contain personal data, and occasionally sensitive personal data, belonging to our client’s staff, customers or users. Where that happens:

The work is carried out under a written agreement, with a scope agreed in advance, and nothing outside that agreed scope is examined.

We act on our client’s instructions in respect of that material, and we do not use it for our own purposes.

Access is restricted to the personnel who need it for the engagement, and findings are handled under confidentiality obligations.

Evidence and working material are retained only for as long as the engagement and the agreement require, and are then deleted or destroyed.

6. How we collect personal data

We obtain personal data:

Directly from you — when you complete the enquiry form on our contact page, email us, telephone us, meet us at an event, or correspond with us during a project.

From the organisation you work for — where a client, prospect, partner or supplier gives us contact details for the people we should deal with.

Automatically — through server logs and the technologies described in section 9 when you use the website.

From third parties — such as service providers who support our operations, or publicly available professional sources where we research a prospective client organisation.

7. Why we use personal data

We use personal data to:

Respond to enquiries and provide information you have asked for.

Scope, agree, deliver, support and administer our services.

Manage contracts, purchase orders, invoicing and payment.

Operate, maintain and improve this website and our internal systems.

Keep our systems and our clients’ engagements secure, and detect, investigate and respond to misuse, fraud or security incidents.

Send business communications and, where permitted, marketing material about our services.

Manage supplier and partner relationships.

Consider applications for roles with us.

Meet legal, regulatory, tax, accounting and record-keeping obligations, and establish or defend legal claims.

8. The legal grounds we rely on

Data protection laws differ between countries, and not every legal ground exists, or is framed the same way, in every jurisdiction. Where a law of the kind described below applies to a particular processing activity, we rely on the ground appropriate to that activity. Depending on the applicable regime, that may be:

Performance of a contract — where processing is needed to agree or deliver a service, or to take steps you have asked for before entering a contract.

Legitimate interests — where we have a genuine business reason, such as securing our systems, understanding how our website is used, or contacting professionals at organisations that may need our services, and that reason is not overridden by the interests or rights of the individual.

Consent — where the applicable law requires it, for example for certain marketing communications or for non-essential tracking technologies. Where we rely on consent you may withdraw it at any time, which does not affect processing carried out beforehand.

Compliance with a legal obligation — where a law that applies to us requires the processing.

Other grounds recognised by the applicable law — such as protecting someone’s vital interests, or a task carried out in the public interest, in the limited circumstances where the relevant regime provides for them.

Some regimes, including the Saudi Personal Data Protection Law and the UAE federal data protection framework, set out their own permitted bases for processing, and these do not map exactly onto the European model. Where such a regime applies, we rely on the grounds that regime provides.

9. Cookies and similar technologies

This section describes what this website actually does today, rather than a generic list. We have checked it against the site as built.

The website does not set advertising or profiling cookies, and no analytics or tracking product is installed on it. On a standard visit to a public page, the site itself does not place cookies on your device. Your browser may store a small amount of local data to support basic display behaviour.

Certain features do involve services provided by other organisations, and those organisations may set cookies or receive technical data such as your IP address when the feature loads:

Google reCAPTCHA — used on our enquiry form to distinguish genuine submissions from automated abuse. It is provided by Google and involves data being sent to Google to assess the interaction. Without it we would be unable to keep the form usable.

Web fonts — the typefaces used across this site are served from our own servers rather than from a third-party font service, so displaying them does not involve a request to an external provider.

AddToAny — social sharing buttons that let readers share our blog articles, provided by a third party. This component loads only on individual article pages; visiting any other page on the site involves no request to that provider.

Caching and security infrastructure — software that keeps the site fast and protects it against attack may set a technical cookie or process your IP address for those purposes.

You can control cookies through your browser settings, including blocking or deleting them, and you can generally prevent third-party components from loading using browser settings or extensions. Restricting them may stop parts of the site, such as the enquiry form or the map, from working properly. Because the site does not currently deploy advertising, profiling or analytics technologies, it does not present a consent banner; if that changes, we will update this policy and introduce appropriate consent controls before deploying such technologies.

10. Analytics

No web analytics or audience-measurement product is installed on this website at the date of this policy. We do not build behavioural profiles of visitors and we do not use the site for advertising measurement.

Our hosting and security infrastructure produces server-side logs, which we use to keep the site available and secure rather than to study individual behaviour. If we introduce an analytics tool in future, we will update this policy to name it and describe what it collects, and we will implement any consent mechanism the applicable law requires before it is deployed.

11. Marketing communications

There is a difference between the two kinds of message we may send you, and it affects your choices:

Service and business communications — replies to your enquiry, information needed to scope or deliver work, contractual and operational notices, and security-related notifications. These are part of the relationship and are not marketing.

Marketing communications — material about our services that we think may be relevant to your organisation.

Where the applicable law requires your consent before we send marketing, we will obtain it. Where the applicable law permits marketing to business contacts on another basis, we rely on that basis and still offer a straightforward way to stop. Several of the regimes relevant to us, including in the UAE and Saudi Arabia, regulate direct and electronic marketing specifically, and we follow the requirements that apply to the audience in question.

You can ask us to stop sending marketing at any time by replying to the message or by contacting us using the details in section 26. We will act on the request without needing a reason. Stopping marketing does not stop necessary service communications about work we are doing for your organisation.

12. When we share personal data

We do not sell personal data, and we do not share it for other organisations’ independent marketing.

We share personal data only where there is a reason to, and then only with:

Our own personnel — employees and contractors who need the information to do their work, on a least-privilege basis. Between our two affiliated companies — our UAE and Pakistan entities share systems and personnel, so personal data may be handled by either where that is necessary to respond to you or deliver a service.

Service providers acting for us — including hosting, email, IT, backup, security and professional services providers, described further in section 13.

Client organisations — where you are a contact at a client, or where an engagement requires us to report to the organisation that commissioned it.

Professional advisers — such as accountants, auditors, insurers and lawyers, where they need the information to advise us.

Authorities — regulators, law enforcement, courts or government bodies where a law that applies to us requires disclosure, or where we need to establish, exercise or defend legal claims. We assess such requests before responding rather than treating them as automatic.

A successor organisation — in the circumstances described in section 24.

13. Processors and subprocessors

Some of our operations depend on specialist providers — for example hosting and content delivery, email, backup, and security tooling. Where such a provider processes personal data on our behalf, it acts as our processor and is not free to use the data for its own purposes.

Where we engage providers of this kind we seek to ensure that written terms are in place covering confidentiality, security, the permitted scope of processing, the handling of any onward transfer, and deletion or return of data at the end of the arrangement.

Where we deliver a service to a client and need to involve another organisation in that delivery, that organisation is a subprocessor for the client engagement. Our contract with the client governs how subprocessors are approved and notified, and clients engaging us for regulated or sensitive work commonly agree specific arrangements with us. If you are a client and need the current list of providers relevant to your engagement, ask us using the details in section 26 and we will provide it under the terms of your agreement.

14. International data transfers

We are a group of two affiliated companies, one in the United Arab Emirates and one in Pakistan, sharing a website, an email domain and common systems. Personal data therefore moves between the UAE and Pakistan in the ordinary course of our work, and may also be accessed from, or stored in, another country where a service provider operates. Cross-border transfer is one of the areas where data protection regimes differ most, and where several of the laws relevant to us impose specific conditions.

Our approach is:

We consider, before transferring personal data across a border, whether the applicable law permits the transfer and on what condition.

Where the applicable regime recognises destinations judged to offer an adequate level of protection, a transfer to such a destination may proceed on that footing.

Where adequacy is not available, we look to put an appropriate safeguard in place — typically contractual protections of the kind the relevant regime provides for, such as standard clauses approved by the competent authority.

Where the applicable regime requires an assessment of the risks of a specific transfer, or notification to or approval from a regulator, we address that requirement before proceeding.

Where a client instructs us to keep particular data within a defined territory, we handle that as a contractual requirement of the engagement.

The Saudi Personal Data Protection Law and its subordinate rules set conditions on transferring personal data outside the Kingdom, and the UAE federal framework likewise regulates transfers abroad. Where either applies to a transfer we are making, we follow the conditions of that regime rather than a generic approach.

We have not named a specific transfer mechanism here because the appropriate mechanism depends on the destination, the regime that applies and the engagement. If you need to know the arrangements relevant to a particular transfer, please contact us.

15. How we protect personal data

Security is our profession, and we apply to our own environment the disciplines we recommend to clients. We describe our controls at the level below deliberately: enough for a procurement or vendor-assurance review to understand our posture, without publishing detail that would help someone attack us.

Access control — access is granted on a least-privilege basis, tied to role and business need, reviewed periodically and removed when someone changes role or leaves.

Authentication — multi-factor authentication is applied to administrative and remote access to our systems.

Encryption — data is protected in transit using current transport encryption, and encryption at rest is applied where appropriate to the system and the sensitivity of the data.

Network and endpoint protection — segmentation, filtering and endpoint controls appropriate to the environment.

Logging and monitoring — security-relevant events are logged and monitored so that unusual activity can be identified and investigated.

Vulnerability and patch management — systems are kept up to date, and weaknesses are identified, prioritised by risk and remediated.

Secure handling of engagement material — findings, evidence and client data from security engagements are held under access restrictions and confidentiality obligations for the duration agreed with the client.

Backup and recovery — backups are taken and recovery is tested so that we can restore service after disruption.

People — staff and contractors are bound by confidentiality obligations and receive security awareness guidance appropriate to their role.

Suppliers — providers with access to personal data are subject to written terms covering security and confidentiality.

No organisation can promise that information will never be compromised, and we do not make that claim. What we do commit to is maintaining controls proportionate to the risk, reviewing them, and acting promptly when something goes wrong.

Where we hold a formal certification or independent attestation, we will say so explicitly and provide evidence on request. We do not claim certifications we do not hold.

16. Personal data incidents

If we identify a security incident affecting personal data, our approach is to:

Investigate promptly to establish what happened, what data and whose data is involved, and whether the incident is ongoing.

Contain the incident and take steps to limit further exposure.

Assess the risk to the individuals concerned, which determines what has to happen next.

Remediate the underlying cause and strengthen controls where the incident reveals a weakness.

Notify the competent regulator where an applicable law requires it, within the timeframe that law sets.

Notify affected individuals where an applicable law requires it, or where we judge it right to do so.

Notify client organisations where our contract with them or the applicable law requires it, and support them in meeting their own obligations where we acted as their processor.

Record the incident and what we learned from it.

Notification deadlines differ between regimes, and we follow the deadline set by whichever law applies to the incident. We have deliberately not stated a single universal notification period here, because doing so would misrepresent how these obligations actually work.

17. How long we keep personal data

We keep personal data only as long as there is a reason to, and then dispose of it. Rather than invent a single period that would not survive contact with reality, we set retention by reference to the purpose:

Enquiries that do not lead anywhere — kept for a limited period to handle follow-up, then removed.

Client and supplier relationships — kept for the life of the relationship and afterwards for as long as needed for contractual, accounting, tax and audit purposes.

Engagement material — kept for the period agreed with the client in the relevant agreement, then deleted or returned.

Security and system logs — kept for the period needed to operate and defend the systems that generate them.

Marketing preferences — a record of an opt-out is kept so that we can continue to honour it.

Recruitment — kept for a limited period after a decision, unless you agree we may keep your details for future roles.

Where a law, regulator or contract sets a minimum retention period, that period governs. Where litigation or an investigation is reasonably in prospect, relevant records are preserved until the matter concludes.

18. Deletion, destruction and anonymisation

When personal data reaches the end of its retention period, or when we are required to erase it, we dispose of it in a way appropriate to the medium — secure deletion for electronic records, and secure destruction for physical media and documents.

In some cases we anonymise or aggregate information instead, so that it no longer identifies anyone and can be retained for statistical or business-planning purposes. Where we do that, we do not attempt to re-identify the data. Backups are overwritten on their own cycle, so data may persist briefly in a backup after deletion from a live system; it remains protected during that period and is not restored into use.

19. Your rights over your personal data

Depending on where you are and which law applies to the processing in question, you may have some or all of the following rights. Not every right exists in every jurisdiction, and most are subject to conditions and exceptions.

To be informed — to know what we do with your personal data, which is the purpose of this policy.

Access — to obtain confirmation of whether we hold personal data about you and a copy of it.

Correction — to have inaccurate or incomplete information put right.

Erasure — to have personal data deleted where there is no continuing basis to keep it.

Restriction — to have processing limited while a question about it is resolved.

Objection — to object to processing carried out on the basis of legitimate interests, and to object to direct marketing at any time.

Portability — to receive certain data you provided in a structured, commonly used electronic format, and to have it sent to another organisation where technically feasible.

Withdrawing consent — where we rely on consent, to withdraw it at any time.

Automated decisions — not to be subject to decisions producing legal or similarly significant effects taken solely by automated means, where the applicable law provides this. We do not currently make decisions of that kind about individuals through this website.

If we hold your data as a processor for a client, we will normally refer your request to that client, who is responsible for responding, and support them in doing so.

20. Making a request

Contact us at info@shieldednetworks.com and tell us what you would like us to do. To help us respond, it helps if you tell us what you are asking for, and enough about your dealings with us — such as the organisation you work for or the address you contacted us from — for us to locate your data.

We may need to confirm your identity before acting, so that we do not disclose someone’s data to the wrong person. We will ask only for what is proportionate to that check, and we will not ask you to send us sensitive documents that we do not need.

We handle requests without charge in normal circumstances and respond within the period set by the applicable law. If a request is unusually complex, or if we need more information from you, we will tell you. If we cannot do what you have asked, we will explain why.

21. Concerns and complaints

If you are unhappy with how we have handled your personal data or your request, please raise it with us first at info@shieldednetworks.com. We would rather hear about a problem and fix it.

You may also have the right to complain to the data protection authority or regulator in your country, or in the country where you believe the issue arose. Which authority that is depends on your location and the law that applies — for example the UAE Data Office in the United Arab Emirates, the Saudi Data and Artificial Intelligence Authority in Saudi Arabia, or the supervisory authority of the relevant member state in the European Economic Area. We have deliberately not reproduced regulator contact details here, because they change; you should obtain them from the authority’s own official website.

JURISDICTION MATRIX

Which regime applies, and when

Privacy rights are not universal. What you can ask for, and who regulates it, depends on where you are and on the nature of the processing. The summary below is a guide to the regimes most likely to be relevant to us; it is not legal advice, and applicability is assessed case by case.

United Arab Emirates

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data has been in force since January 2022, with the UAE Data Office as the federal authority. This is the UAE regime relevant to us: we are established in the Dubai Silicon Oasis free zone. We do not claim that the DIFC or ADGM regimes apply to us — those financial free zones operate their own separate data protection laws, which govern entities established within them.

Saudi Arabia

The Personal Data Protection Law has been in force since September 2023, with a compliance date in September 2024, supported by implementing rules and separate requirements on transferring personal data outside the Kingdom. It is administered by the Saudi Data and Artificial Intelligence Authority. It can be relevant to processing that concerns individuals in the Kingdom even where the processing happens elsewhere.

EU / EEA and United Kingdom

The EU General Data Protection Regulation, and in the UK the UK GDPR together with the Data Protection Act 2018, may apply where our activities fall within their territorial scope — for example where we offer services to individuals in those territories or monitor their behaviour. Where they apply, the full set of rights in section 19 is generally available.

Qatar, Bahrain and Oman

Each has a generally applicable personal data protection law: Qatar’s Law No. 13 of 2016, Bahrain’s Law No. 30 of 2018, and Oman’s law issued by Royal Decree 6/2022 with executive regulations following in 2024. Where one of these applies to processing we carry out, we handle the personal data in accordance with it, including the rights it grants.

Kuwait

Kuwait does not have a general personal data protection statute of the kind found in its neighbours. Data privacy rules issued by the Communication and Information Technology Regulatory Authority apply to licensed telecommunications and internet service providers rather than to businesses generally. We therefore make no claim that a Kuwaiti data protection regime governs our processing, while remaining subject to any other Kuwaiti law that applies to us.

Pakistan

Pakistan does not currently have a comprehensive personal data protection statute in force. A Personal Data Protection Bill has been developed and revised over several years but, as at the date of this policy, remains draft legislation and is not law. Other Pakistani legislation, including the Prevention of Electronic Crimes Act 2016, sector rules and the obligations attaching to a company registered with the Securities and Exchange Commission of Pakistan, can still be relevant — our Pakistani affiliate is registered there. We will update this policy if a general data protection law is enacted.

22. Children

This website and our services are directed at organisations and the professionals who work in them. They are not aimed at children, and we do not knowingly collect personal data from children through this website. If you believe a child has provided us with personal data, please contact us and we will look into it and remove the data where appropriate.

23. Third-party websites and services

Our site links to other organisations’ websites, and includes components provided by third parties as described in section 9. Once you follow a link to another website, or once a third-party component loads, that organisation’s own privacy practices apply to what it collects. We do not control those practices and are not responsible for them. We suggest reading the privacy notice of any third-party site you visit.

24. Business transfers

If our business or part of it is sold, merged, restructured, or if assets are transferred, personal data may be transferred to the counterparty or a successor as part of that transaction, and may be disclosed to advisers and prospective counterparties beforehand under confidentiality obligations. Where that happens, the data remains subject to protections consistent with this policy, and we will notify you where an applicable law requires it.

25. Changes to this policy

We review this policy periodically and update it when our practices change, when we deploy new technology on the website, or when the legal position moves. The effective date and last-updated date are shown at the top of the page.

Where a change materially affects how we use personal data, we will take reasonable steps to bring it to the attention of those affected, which may include a notice on this website or a direct message. Continuing to use the site after an update means the current version applies to your use of it.

26. Contact us

For any question about this policy, about how we handle personal data, or to make a request under section 20:

Shielded Networks FZCO (United Arab Emirates)
Building A1, Dubai Digital Park, Dubai Silicon Oasis, Dubai, United Arab Emirates
Telephone: +971 50 293 7256

Shielded Networks (SMC-Private) Limited (Pakistan)
Street 7, I-10/3, Islamabad 44800, Pakistan
Telephone: +92 345 945 1812

Email for either entity: info@shieldednetworks.com

If your question relates to an engagement we are carrying out for a client organisation, please also raise it with that organisation, since it may be the controller of the data in question.

Important note on scope and legal effect

This policy describes how Shielded Networks handles personal data. It is written to inform, and it does not replace or override the law that applies to any particular processing, nor does it create rights beyond those the applicable law provides.

Whether a given data protection regime applies to particular processing depends on the circumstances — where the individual is, where the processing happens, what service is involved and who has instructed it. Separate or additional privacy information may be provided for specific services, client engagements, recruitment or employment, and where a contract with a client sets out different or additional obligations, that contract governs that engagement.

This policy is not legal advice.

Questions about how we handle your data?

Ask us directly. We would rather answer a privacy question properly than have you guess from a policy page.

Contact Shielded Networks